CISSP Identity and Access Management Practice Question
An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Orphaned account
An orphaned account is one that remains active after an employee has left, posing a security risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Orphaned account
Why this is correct
An orphaned account is an active user account that no longer has an associated legitimate user, typically because the employee has left the organization but their account was not properly deprovisioned or disabled. This oversight creates a significant security vulnerability, as the account could be exploited by an attacker or the former employee themselves to gain unauthorized access to systems and data. The discovery of a former employee's active account directly indicates a failure in the organization's identity and access management offboarding process.
- ✗
Privilege escalation
Why it's wrong here
Privilege escalation refers to the act of an attacker or user gaining higher access rights than they were originally authorized for, often by exploiting system vulnerabilities or misconfigurations. While a former employee *could* attempt to escalate privileges if they regained access, the core issue described is the *existence* of their account post-employment, not the act of increasing permissions from an already established, lower-level access. The problem is the account's continued presence, not a change in its privilege level.
- ✗
Social engineering
Why it's wrong here
Social engineering involves manipulating individuals into performing actions or divulging confidential information, often through psychological tactics like phishing, pretexting, or baiting. This method targets human vulnerabilities rather than technical system flaws or administrative oversights. The scenario describes a technical oversight in account deprovisioning, not a situation where an individual was tricked into creating or maintaining the former employee's account, nor does it describe how the account was discovered.
- ✗
Insider threat
Why it's wrong here
An insider threat typically originates from a current employee, contractor, or business partner who has authorized access to an organization's assets and misuses that access, either intentionally or unintentionally, to negatively affect the organization. While a former employee with an active account could pose a risk, the term 'insider threat' specifically implies a *current* trusted relationship. The primary issue here is the failure to revoke access for someone who is no longer an insider, rather than malicious activity by a current one.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.